Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
82.322exploits catalogados
38.524CVEs com exploração pública
24.695testados em laboratório
TodosReferência 24.711Exploit-DB 24.485GitHub PoC 15.927VulnCheck XDB 9.231Nuclei 4.455Metasploit 3.513✓ só verificadosrecentespopularesrisco
82.322 exploits
Exploit-DB✓ VexDay Proof
Music Gallery Site v1.0 - SQL Injection on page Master.php
SourceCodester Music Gallery Site GET Request Master.php sql injection
33RISCO
abrir ↗GitHub PoC★ 1
CVE-2023-23752
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗Exploit-DB
Arris Router Firmware 9.1.103 - Remote Code Execution (RCE) (Authenticated)
Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.
53RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Auto Dealer Management System 1.0 - Broken Access Control Exploit
SourceCodester Auto Dealer Management System Users.php access control
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Best pos Management System v1.0 - Remote Code Execution (RCE) on File Upload
SourceCodester Best POS Management System Image save_settings unrestricted upload
33RISCO
abrir ↗Exploit-DB
Dompdf 1.2.1 - Remote Code Execution (RCE)
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (
60RISCO
abrir ↗GitHub PoC
qaisarafridi/cve-2021-3129
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RISCO
abrir ↗GitHub PoC★ 1
LHXHL/Minio-CVE-2023-28432
Minio Information Disclosure in Cluster Deployment
100RISCO
abrir ↗GitHub PoC★ 8
GoAnywhere MFT CVE-2023-0669 LicenseResponseServlet Deserialization Vulnerabilities Python RCE PoC(Proof of Concept)
Fortra GoAnywhere MFT License Response Servlet Command Injection
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Employee Task Management System v1.0 - SQL Injection on edit-task.php
SourceCodester Simple Food Ordering System process_order.php cross site scripting
28RISCO
abrir ↗Exploit-DB
Agilebio Lab Collector Electronic Lab Notebook v4.234 - Remote Code Execution (RCE)
AgileBio Electronic Lab Notebook v4.234 was discovered to contain a local file inclusion vulnerability.
41RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Auto Dealer Management System v1.0 - SQL Injection on manage_user.php
SourceCodester Auto Dealer Management System sql injection
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Simple Food Ordering System v1.0 - Cross-Site Scripting (XSS)
SourceCodester Simple Food Ordering System process_order.php cross site scripting
28RISCO
abrir ↗Exploit-DB
Mitel MiCollab AWV 8.1.2.4 and 9.1.3 - Directory Traversal and LFI
A Directory Traversal vulnerability in the web conference component of Mitel MiCollab AWV before 8.1.2.4 and 9.x before
50RISCO
abrir ↗GitHub PoC
BaconCriCRi/PoC-CVE-2022-4939-
WCFM Membership <= 2.10.0 - Unauthenticated Privilege Escalation
48RISCO
abrir ↗VulnCheck XDB
initial-access
[20230201] - Core - Improper access check in webservice endpoints
100RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Music Gallery Site v1.0 - SQL Injection on music_list.php
SourceCodester Music Gallery Site GET Request music_list.php sql injection
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Auto Dealer Management System v1.0 - SQL Injection
SourceCodester Auto Dealer Management System sql injection
33RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Auto Dealer Management System v1.0 - SQL Injection in sell_vehicle.php
SourceCodester Auto Dealer Management System sql injection
33RISCO
abrir ↗Exploit-DB
Provide Server v.14.4 XSS - CSRF & Remote Code Execution (RCE)
Cross Site Scripting (XSS) vulnerability in Provide server 14.4 allows attackers to execute arbitrary code through the s
33RISCO
abrir ↗Exploit-DB
Calendar Event Multi View 1.4.07 - Unauthenticated Arbitrary Event Creation to Cross-Site Scripting (XSS)
Calendar Event Multi View < 1.4.07 - Unauthenticated Arbitrary Event Creation to Stored XSS
33RISCO
abrir ↗Exploit-DB
itech TrainSmart r1044 - SQL injection
A SQL injection vulnerability in I-Tech Trainsmart r1044 exists via a evaluation/assign-evaluation?id= URI.
41RISCO
abrir ↗Exploit-DB
ImageMagick 7.1.0-49 - DoS
ImageMagick 7.1.0-49 is vulnerable to Denial of Service. When it parses a PNG image (e.g., for resize), the convert proc
55RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Answerdev 1.0.3 - Account Takeover
Improper Access Control in answerdev/answer
48RISCO
abrir ↗Exploit-DB
ImageMagick 7.1.0-49 - Arbitrary File Read
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RISCO
abrir ↗Exploit-DB
CKEditor 5 35.4.0 - Cross-Site Scripting (XSS)
CKSource CKEditor 5 35.4.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Full Featured CK
33RISCO
abrir ↗Exploit-DB
Secure Web Gateway 10.2.11 - Cross-Site Scripting (XSS)
XSS in Skyhigh Security SWG
33RISCO
abrir ↗Exploit-DB
Control Web Panel 7 (CWP7) v0.9.8.1147 - Remote Code Execution (RCE)
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISCO
abrir ↗Exploit-DB
Dell EMC Networking PC5500 firmware versions 4.1.0.22 and Cisco Sx / SMB - Information Disclosure
Dell EMC Networking X-Series firmware versions 3.0.1.2 and older, Dell EMC Networking PC5500 firmware versions 4.1.0.22
46RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.